Repository navigation
ci: pin GitHub Actions to commit SHAs - #1204
Closed
chopmob-cloud wants to merge 1 commit into
Closed
chopmob-cloud wants to merge 1 commit into
chopmob-cloud wants to merge 1 commit into
Conversation
Pin the GitHub Actions in .github/workflows to full-length commit SHAs with version comments. A mutable tag can be re-pointed after review, so pinning to a commit SHA is the OpenSSF Scorecard Pinned-Dependencies control. Ref-pinning only, same versions, no functional change. Generated with pinact; each SHA verified to resolve to its version tag. Signed-off-by: AlgoVoi <chopmob@gmail.com>
Collaborator
|
I'm not really convinced by the value of pinning official github actions: while I can understand this in some professional hardened environment, I think given the high rate of evolution of this project we should stay on the edge. |
Collaborator
|
+1 I also think this is overkill for the official GH Actions |
Contributor
Author
|
Not a problem at all, and thanks for the consideration. Completely understand the call for first-party actions in a fast-moving project. Appreciate you both taking the time to look. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Pins the GitHub Actions in
.github/workflowsto full-length commit SHAs with# vXversion comments, bringing this repo in line with the sibling repo a2a-go, which is already fully pinned.Why
A mutable tag like
@v7can be moved to new code after review, so a compromised or hijacked action tag would run with this workflow's permissions. Pinning to a commit SHA is the OpenSSF Scorecard "Pinned-Dependencies" control and the GitHub-recommended practice. This repo already runs Dependabot for thegithub-actionsecosystem, so Dependabot keeps the SHA pins current (it bumps the SHA and the# vXcomment together).What
uses:across 16 workflow files to its exact commit SHA, keeping a# vXversion comment. Same versions, no upgrades or downgrades.pinact; each pinned SHA was verified to resolve to the version in its comment via the GitHub API.